During its launch of the latest HPE ProLiant Compute Gen12 servers, HPE made the claim that they were the world’s first to be “quantum resistant”. So the natural next questions are a) what does quantum resistance mean and b) why should I care?
The answer to the first question is relatively simple. Security experts believe that when quantum computers appear, hackers will use them to access data that is protected by current encryption methods. And that’s a today problem rather than a tomorrow problem, because hackers can steal highly confidential but encrypted data in the hope that it’s valuable in the future.
Not everyone needs to care. Those in the front line include government agencies, but also those organisations who supply such government with data. Financial data is also at risk.
How HPE’s quantum-resistant technology works
The key, according to Scott Schaffer, VP and Chief Technologist, Compute at HPE, comes in a combination of firmware and HPE’s iLO software.
“HPE ProLiant Compute Gen12 are the first servers… with secure firmware signing against future quantum computing attacks embedded into HPE Integrated Lights-Out 7 (iLO) silicon root of trust,” he said.
This means are also the first to be compliant with the NIST and CNSA 2.0 quantum resistance requirements. Namely FIPS 140-3.
These require “the implementation of post-quantum algorithms to protect low-level firmware and software components in HPE iLO7 from being compromised when a quantum computing threat arises”.
We cover HPE iLO 7 separately, but in short it’s HPE’s server management technology.
HPE’s safeguards against quantum threats
Schaffer explains that existing cryptographic algorithms could be easy to break by quantum computers.
These include “RSA (Rivest-Shamir-Adelman) and ECC (elliptic-curve cryptography), which are widely used for securing communications and data,” he said.
“To address this threat, cryptographic systems are increasingly adopting quantum-resistant algorithms. One such algorithm is the Leighton-Micali Signature (LMS) scheme, which is based on hash functions.
“LMS is considered to be resistant to quantum attacks because it relies on the hardness of certain hash-based problems that quantum computers are not expected to solve efficiently. This is how HPE ProLiant Compute Gen 12 signs its firmware.”
Digging into the detail
Schaffer then detailed how HPE’s LMS firmware signing (it’s using SHA-256/192) can help protect a server from attacks by quantum computers. All the below are direct quotes:
- Quantum Resistance: LMS uses hash-based cryptographic techniques, which are believed to be secure against attacks by quantum computers. Unlike traditional algorithms which can be broken by Shor’s algorithm run on a sufficiently powerful quantum computer, hash-based schemes like LMS do not have known vulnerabilities to such attacks.
- Digital Signatures: LMS provides a method for generating and verifying digital signatures. Digital signatures are used to authenticate the identity of entities and to ensure the integrity of data. By using a quantum-resistant algorithm, LMS ensures that these signatures remain secure even in the presence of quantum adversaries.
- Secure Firmware Updates: HPE iLO 7 relies on secure boot processes and secure firmware updates to ensure that only authenticated and untampered firmware is executed. By using LMS for signing firmware updates, the integrity and authenticity of these updates can be guaranteed, protecting the server from malicious firmware that could be introduced by an attacker, including those with quantum capabilities.
- Long-term Security: LMS offers long-term security assurances. As quantum computing technology evolves, servers that use quantum-resistant algorithms will be better positioned to remain secure over time, without needing immediate and potentially disruptive changes to their cryptographic infrastructure.
- Implementation in HPE iLO 7: Within the iLO environment, LMS can be used for various security functions such as authenticating remote management commands, securing communication channels, and ensuring the integrity of critical system components. This ensures that even if an attacker has access to a quantum computer, they cannot easily compromise the server’s security.
Read more about HPE ProLiant Compute Gen12 server family here.
Related HPE articles